Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Getting monorepo-symlink-test Security Vulnerability warning due to resolve package of email-templates #457

Open
sadashiv-sumasoft opened this issue Dec 1, 2023 · 0 comments
Labels

Comments

@sadashiv-sumasoft
Copy link

Hello,
We discovered that your package depends on one of the transitive dependent packages that is causing the critical severity in our AWS inspector.
We discovered this while utilizing the AWS Inspector Scan Vulnerabilities tool to find a vulnerability. The malicious package is called monorepo-symlink-test.

Transitive dependency on the concern package given below.

email-templates@11.1.1
└─┬ @ladjs/consolidate@1.0.3
└─┬ pug@3.0.2
└─┬ pug-filters@4.0.0
└── resolve@1.22.8

I discovered after doing some study that a package contains the name of the malicious package in their package.json file located under the node_module's rest->resolver->multirepo->package.json within the resolve library's resolve module.

In order to prevent us from receiving the security alert, would you kindly remove the undesirable name from that package or remove it entirely?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant